COPPA Penalties: How the FTC Actually Calculates Per-Violation Fines
COPPA fines aren't a single flat number, they're calculated per violation, and the FTC's definition of a 'violation' is broader than most businesses expect. Here's how the math actually works.
COPPA authorizes civil penalties on a per-violation basis, with the maximum amount per violation set by statute and adjusted periodically for inflation by the FTC. The headline number gets attention, but the more important detail for assessing real exposure is what actually counts as one violation, because that’s what determines how the total adds up.
What counts as a single “violation”
This is the detail that turns a moderate-sounding per-violation cap into a potentially large total exposure. The FTC has generally treated each child whose data was collected without proper consent as a separate violation, not each policy or each day the practice continued. A site that collected personal information from a large number of children without verifiable parental consent is exposed to the per-violation maximum multiplied by the number of children affected, which is how COPPA settlements can reach large aggregate figures even when the underlying per-violation cap sounds contained in isolation.
Why this matters more for higher-traffic sites
The per-child calculation means COPPA exposure scales directly with audience size in a way that flat statutory fines don’t. A children’s app or site with a small, contained user base and a genuine compliance gap faces meaningfully less aggregate exposure than a high-traffic platform with the same underlying gap, simply because more children’s records are implicated. This is one of the reasons COPPA enforcement has historically concentrated on larger platforms and services, not because smaller sites are exempt, but because the arithmetic makes large-scale violations the more visible, higher-dollar cases.
Factors that influence the actual penalty within the cap
The statutory maximum per violation is a ceiling, not a fixed amount. In practice, penalty amounts actually assessed or negotiated in FTC actions and settlements have reflected factors like:
- The egregiousness of the violation, an outright failure to implement any verifiable consent mechanism weighs differently than a good-faith mechanism with a specific gap.
- Whether the conduct was knowing, actual knowledge that a site was collecting from children under 13 tends to be treated more seriously than an ambiguous “directed to children” judgment call made in good faith.
- The company’s compliance history, repeat or continued violations after prior notice are treated more seriously than a first-time gap.
- The company’s ability to pay, and the deterrent value the FTC is trying to achieve.
Usercentrics
Since penalty exposure scales with the number of children whose data was collected without proper consent, knowing exactly how many users triggered your child-directed or age-screen logic is directly relevant if a gap is ever found. Usercentrics' consent reporting gives you that kind of granular, timestamped record rather than an estimate after the fact.
Beyond civil penalties
Monetary fines aren’t the only consequence in FTC COPPA actions. Settlements have also included requirements to delete improperly collected data, implement specific compliance programs going forward, submit to ongoing compliance monitoring or reporting, and in some cases obtain independent assessments of the compliance program for a period of years. For an ongoing business, these structural requirements can be more operationally significant than the monetary penalty itself.
The bottom line
COPPA’s per-violation penalty structure means the real exposure question isn’t “what’s the maximum fine,” it’s “how many children’s records were affected,” since that’s the multiplier that actually drives the total. A compliance gap on a small, low-traffic children’s feature and the same gap on a high-traffic platform are not the same risk, even though the underlying legal violation looks identical on paper.
This guide is educational and not legal advice. For your specific situation, consult a privacy attorney.